Trojan

Trojan.Agent.FKKW information

Malware Removal

The Trojan.Agent.FKKW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.FKKW virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

How to determine Trojan.Agent.FKKW?


File Info:

crc32: DD1BBD50
md5: 970141c334965b51e960fc287106ba9a
name: 970141C334965B51E960FC287106BA9A.mlw
sha1: 10c792d0e37a4b55669e38d34bfc4f7290592e9d
sha256: a44afa0907b48e04657561e24ca6e009777c607827d08086dff676b1249b9de9
sha512: ce65c15bfaa4cdefe4cdea322be4523d497e5804fc1c7e2da433a35ef2cbfb501020d7bb401ae8d1d829dc9c396b1f653438fa833b4bfa535b550c36c34bfa58
ssdeep: 12288:VE2DFZrTO3XZ3jLOBWTNvFD1VeubeMl2005W7eQT:VrrTO3J3WwZv91VeAlXw
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2001
InternalName: SpecialFX
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: SpecialFX Application
ProductVersion: 1, 0, 0, 1
FileDescription: SpecialFX MFC Application
OriginalFilename: SpecialFX.EXE
Translation: 0x0409 0x04b0

Trojan.Agent.FKKW also known as:

LionicTrojan.Win32.Trickpak.4!c
DrWebTrojan.KillProc2.16352
CylanceUnsafe
SangforTrojan.Win32.Trickpak.gen
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/GenKryptik.106325e6
K7GWTrojan ( 0057f7bd1 )
K7AntiVirusTrojan ( 0057f7bd1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FHPC
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.Agent.FKKW
MicroWorld-eScanTrojan.Agent.FKKW
Ad-AwareTrojan.Agent.FKKW
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Worm.hc
FireEyeGeneric.mg.970141c334965b51
EmsisoftTrojan.Agent.FKKW (B)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Trickpak.gen
GDataWin32.Trojan.PSE.TR0KKF
AhnLab-V3Trojan/Win.Infostealer.C4556322
McAfeeRDN/Generic.dx
MAXmalware (ai score=84)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0DGG21
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Trickpak.FHPC!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Kryptik.HxsAoo8A

How to remove Trojan.Agent.FKKW?

Trojan.Agent.FKKW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment